state: refresh policy nodes inside the peer map build

One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
This commit is contained in:
Kristoffer Dalby
2026-09-25 17:36:26 +00:00
parent 311d9323e0
commit 21f6e46fb8
17 changed files with 1085 additions and 148 deletions
+2 -4
View File
@@ -134,14 +134,12 @@ func registerACL(api huma.API, b Backend) {
}
cs, err := b.State.ReloadPolicy()
b.Change(cs...)
if err != nil {
return nil, huma.Error500InternalServerError("reloading policy", err)
}
if len(cs) > 0 {
b.Change(cs...)
}
return streamPolicy([]byte(updated.Data), aclContentType(in.Accept)), nil
})
}
+8 -8
View File
@@ -232,12 +232,12 @@ func registerDevices(api huma.API, b Backend) {
}
_, nodeChange, err := b.State.RenameNode(node.ID(), in.Body.Name)
b.Change(nodeChange)
if err != nil {
return nil, mapError("renaming device", err)
}
b.Change(nodeChange)
return &emptyOutput{}, nil
})
@@ -278,12 +278,12 @@ func registerDevices(api huma.API, b Backend) {
}
_, nodeChange, err := b.State.SetNodeTags(node.ID(), in.Body.Tags)
b.Change(nodeChange)
if err != nil {
return nil, mapError("setting device tags", err)
}
b.Change(nodeChange)
return &emptyOutput{}, nil
})
@@ -311,12 +311,12 @@ func registerDevices(api huma.API, b Backend) {
}
_, nodeChange, err := b.State.SetNodeExpiry(node.ID(), nil)
b.Change(nodeChange)
if err != nil {
return nil, mapError("setting device key expiry", err)
}
b.Change(nodeChange)
return &emptyOutput{}, nil
})
@@ -341,12 +341,12 @@ func registerDevices(api huma.API, b Backend) {
}
updated, nodeChange, err := b.State.SetApprovedRoutes(node.ID(), approved)
b.Change(nodeChange)
if err != nil {
return nil, mapError("setting device routes", err)
}
b.Change(nodeChange)
return &deviceRoutesOutput{Body: routesFromView(updated)}, nil
})